First published: Mon Dec 06 2021(Updated: )
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary remote code execution as root. The vulnerability was caused by untrusted input (received by the server) being passed to system calls.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Kaseya Unitrends Backup | >=10.0<10.5.5 | |
>=10.0<10.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-43033 is classified as critical due to the potential for arbitrary remote code execution as root.
To mitigate CVE-2021-43033, you should upgrade the Kaseya Unitrends Backup Appliance to version 10.5.5 or later.
CVE-2021-43033 affects Kaseya Unitrends Backup versions prior to 10.5.5.
CVE-2021-43033 can be exploited to achieve arbitrary remote code execution, allowing attackers to gain root privileges.
The vulnerability in CVE-2021-43033 is caused by untrusted input being passed to system calls in the bpserverd daemon.